Clop created custom web shell for Windchill data theft attacks
Reported exploitedPTC WindchillClopFlexPLMOur summary
ReliaQuest identified a custom-built Java web shell attributed to the Clop ransomware gang, specifically engineered for PTC Windchill and FlexPLM servers. This implant leverages the critical remote code execution vulnerability CVE-2026-12569 to decrypt stored credentials and exfiltrate files from application vaults. Because the tool integrates directly with Windchill's internal APIs, database queries run under the application's service identity, potentially evading standard detection methods. Organizations running affected versions are urged to apply patches immediately and investigate any unusual JSP files referencing the 'X-windchill-req' header.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.